Two WordPress Plugins Need Updates, Plus 4 Tech Stories
WordPress administrators have two fresh security updates worth making before breakfast, and one of them has a wonderfully weird failure mode: an attacker can plant something today that does nothing until an administrator restores a backup later. There’s also a hosting-control-panel attack that briefly rerouted part of the internet, a Dropbox breach caused by an old Lenovo login relationship, a new Google Search control for publishers, and two states backing away from Flock’s license-plate surveillance network.
Two popular WordPress plugins need security updates
If you run All-in-One WP Migration and Backup, update it to 7.110 or newer. If you run Gravity Forms, update to 3.0.3 or newer. Both patches were actually released August 20, but the full vulnerability details became public this week, and the details are different enough that they’re worth understanding rather than just collecting two scary CVE numbers.
All-in-One WP Migration has more than five million active installations. CVE-2026-19949, rated 8.8, is what security people call a second-order SQL injection. Normally an SQL-injection attack tries to make a database execute malicious input right away. Here, an unauthenticated visitor can plant the dangerous data first. It sits there harmlessly until an administrator later exports and restores a site archive. During that restore, the plugin can treat the stored data as part of a database command, potentially exposing the plugin’s secret key and opening a path to remote code execution.
That restore requirement matters. This is not “visit any site running 7.109 and instantly own it.” But it also means the payload can be waiting for an administrator to do something completely normal months later. The fix is still the easy part: install 7.110 or newer.
Gravity Forms has more than one million active installations, and CVE-2026-19513 affects versions through 3.0.2. The vulnerable setup needs a public form with a File Upload field configured to accept multiple files. Under those conditions, an unauthenticated attacker can confuse the plugin’s multi-part upload state and choose the temporary filename, potentially placing a specially crafted image or PDF under a .php or .html name.
Whether that becomes full remote code execution depends partly on the web server. Gravity Forms places an .htaccess file in the temporary directory to stop PHP execution, which helps on Apache-style servers that honor it. NGINX doesn’t use .htaccess, so the server’s own PHP rules become important. Even without PHP execution, a malicious HTML file can create a stored cross-site-scripting problem.
I wouldn’t spend much time trying to decide which one is scarier. Check the versions, update them, and move on with your day.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
Attackers hijacked internet routing to push a real software update
Softaculous disclosed an incident that sounds like somebody combined three different infrastructure nightmares into one.
Between August 28 and 30, an unauthorized network announced a more-specific BGP route for a block of IP addresses used by Softaculous. BGP is the system internet providers use to tell one another, essentially, “send traffic for these addresses through me.” More-specific routes normally win, so networks that accepted the bad announcement sent traffic meant for Softaculous to the attacker instead.
That was bad enough. The attacker then obtained valid TLS certificates for affected Softaculous domains because the certificate authority’s own domain-validation traffic followed the hijacked route too. So a server talking to what it believed was a legitimate HTTPS update endpoint could get the wrong server with a certificate that still checked out.
Virtualizor, Softaculous’s virtualization-management product, did not cryptographically verify update packages. Softaculous says a small number of installations therefore received a malicious update. It cannot produce a definitive victim list because those requests hit the attacker’s server, not Softaculous’s logs.
If you run Virtualizor, check for /etc/systemd/system/java-jre-update.service, rotate and restrict API credentials, review SSH keys, accounts, cron jobs and outbound connections, and update to 3.2.9.9. Softaculous says it is adding code signing to its packages.
That last part is the larger lesson. HTTPS proved that the server at the other end controlled the domain at that moment. It did not prove that the software package itself was authentic. Those are different trust problems, and this incident managed to exploit the gap between them.
A forgotten Lenovo login opened about 5,000 Dropbox accounts
Dropbox says attackers compromised about 5,000 accounts between August 4 and August 21 through what Lenovo describes as a “legacy integration” between Lenovo ID and Dropbox.
The mechanism is more interesting than the number. Dropbox allowed a verified Lenovo ID to authenticate a corresponding Dropbox user. A problem with Lenovo’s email-verification process let attackers create Lenovo IDs using other people’s email addresses, then use those identities to enter Dropbox accounts tied to the same addresses. The affected Dropbox accounts did not have Dropbox two-factor authentication enabled.
Dropbox says files were viewed or downloaded in fewer than one-third of the compromised accounts. It has terminated Lenovo-authenticated sessions, removed the links between Lenovo IDs and Dropbox accounts, and now requires a Dropbox password before that path can be used. Lenovo says its own customers were not affected and that its investigation continues.
If Dropbox notified you, take the notification seriously: change the Dropbox and email passwords from a trusted device, enable two-step verification, review sessions and account activity, and think about what was stored there. If you weren’t notified, this is still a decent five-minute reminder to enable MFA.
The broader lesson is one I wish software companies would learn before the word “legacy” appears in the incident report. Every old single-sign-on relationship is another organization whose identity checks you are trusting to protect your account.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Google now lets websites opt out of AI Search
Google’s new Search Console control for generative AI Search finished rolling out worldwide on August 31. Website owners can now tell Google not to use their pages to appear in or ground responses in AI Overviews, AI Mode and AI-powered features in Discover.
There is a catch, and at least Google is stating it plainly: opting out also means giving up traffic and impressions from those generative-AI features. Google says the choice does not affect ranking in its non-generative search features.
That turns a philosophical argument into a business decision. A publisher can say, “Don’t use my work in AI answers,” but the price is also, “Don’t send me visitors from those answers.” European regulators are already asking publishers whether that is a meaningful choice as part of an antitrust investigation into Google’s AI Search features.
For a small business, I would not flip this switch just because AI scraping makes you angry. Look at Search Console first. If AI Search is sending useful traffic, understand what you’re giving up. If it’s consuming your content without producing meaningful visits, now you at least have a real control instead of another robots.txt argument about what a crawler ought to do.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Florida and Texas are backing away from Flock cameras
Flock Safety’s automated license-plate-reader network has reached the point where two large states are now putting on the brakes.
Florida’s Department of Transportation revoked general-use permits for automated license-plate readers on state highways effective August 31 and gave agencies 30 days to remove the cameras. Texas, meanwhile, has ordered state agencies to stop funding Flock systems. TechCrunch reports that Flock now has roughly 130,000 license-plate readers across the United States.
These cameras can be genuinely useful for finding stolen cars, locating missing people and connecting vehicles to crimes. The problem is that a plate reader does more than answer “is this stolen car here right now?” It creates a searchable historical record of where vehicles have been seen, and those records can be shared across agencies. Recent cases have included officers accused of using the system to track people without authorization, along with broader concerns about accuracy, cybersecurity and cross-jurisdiction data sharing.
This is not a nationwide ban, and Florida’s order is specifically about state highway right-of-way. Local systems elsewhere can continue operating under their own rules. But the political direction is notable: the privacy debate has moved from whether these databases are theoretically abusable to what limits should exist now that documented misuse is part of the record.
I don’t think the useful answer is “plate readers are evil” any more than it is “if police can use it, more data must be better.” The hard questions are retention, audit trails, who gets access, what counts as a legitimate search, and how far a local police department’s data should travel. We’ve gotten very good at installing sensors. Governance usually arrives a few years later, looking slightly out of breath.
That’s the thread tying most of today together: old trust relationships have consequences. A backup restore trusts yesterday’s database content. Dropbox trusted an old Lenovo identity link. Virtualizor trusted HTTPS without independently signing its update. Flock asks communities to trust that a huge searchable movement database will be used properly. The boring work is deciding where that trust should stop.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Wordfence: All-in-One WP Migration second-order SQL injection
- Wordfence: Gravity Forms arbitrary file upload vulnerability
- Virtualizor: Security Incident — BGP Hijacking
- Softaculous: BGP hijacking incident update
- Reuters: Dropbox says about 5,000 accounts were compromised
- Google: New controls and insights for website owners
- Reuters: EU regulators quiz publishers on Google’s AI Search opt-out
- Florida DOT: Revocation of automated license-plate-reader permits
- TechCrunch: Florida and Texas move to block Flock cameras
